CompyMax

HIPAA for MSPs

Your healthcare clients assume that because you run their IT, HIPAA is handled. Most MSPs end up doing some of it for free, in email, with no defined scope. This is how to turn that into a service line with a deliverable, a price and a boundary.

Last reviewed .

1. You are almost certainly a business associate

The threshold is lower than most providers assume. You do not have to handle patient records deliberately — persistent administrative access to systems that contain them is generally enough. If you manage a clinic’s servers, endpoints, email tenancy or backups, assume you are in scope and need a signed business associate agreement with that client.

That agreement flows downhill too. Your own subcontractors and the tools you use to deliver the service — remote monitoring, backup, documentation platforms — need agreements with you where they touch client data.

2. Separate your obligations from your client’s

These get conflated constantly, and conflating them is how MSPs end up owning risk they were never paid for.

  • Yours: your own risk analysis, your own staff training, your own policies, safeguards on the tools you use, and breach notification to your clients if you cause one.
  • Theirs: their risk analysis, their workforce training, their policies, their patient-facing processes, and notification to individuals and regulators.

You can operate the second list on their behalf as a service. You cannot absorb it — and you should say so in writing.

3. What the client is actually buying

Not a risk assessment. Clients buy compliance software the week something forces them to: an insurer’s renewal questionnaire, a hospital partner’s vendor review, a payer contract with a security addendum, or a scare after an incident. In every case the thing they need is a credible, dated evidence pack and someone to say it is handled.

Package it that way. “We run your HIPAA programme and produce your evidence pack” sells. “We provide a risk assessment tool” does not.

4. Packaging and pricing

A workable structure is a flat monthly per-client fee covering the programme — assessment, remediation tracking, policies, training, agreement register, incident log and a refreshed evidence pack — plus hourly work for anything that turns into a project, like closing a technical gap the assessment surfaces.

Platform cost is $49 per client organization per month, falling to $39 at ten clients and $29 at twenty-five. Billing $99–199 per client leaves room for the hour or two a month a well-run programme actually takes once it is set up.

5. Where MSPs get into trouble

  • Promising compliance. Never say a client is compliant or will pass an audit. Say what you do: run the programme, track the work, produce the evidence.
  • Giving legal advice. Breach determination is a legal judgement. Document the facts and the four-factor assessment; route the decision to their counsel.
  • Unbounded scope. If compliance work lives in your helpdesk queue with no line item, it expands until it is unprofitable.
  • No agreement with your own vendors. Easy to overlook, and the first thing a thorough reviewer checks.

6. A ninety-day rollout

Weeks 1–2: get your own house in order. Run your own assessment, sign agreements with your subcontractors, train your staff. You cannot sell a programme you do not operate.

Weeks 3–4: pick two friendly clients. Run their assessments, produce their first evidence packs, and time how long it actually takes. That number is your pricing model.

Weeks 5–12: roll it into renewals. The pack you produced for the first two clients is the sales collateral for the rest.

Questions MSPs ask

What is the role of a business associate?
To perform a function involving protected health information on a covered entity's behalf — and, having taken that role, to sign a business associate agreement, implement Security Rule safeguards, report breaches to the covered entity, and carry direct liability for its own failures. For an MSP, 'function' includes simply administering the systems the information lives in, even if you never deliberately look at it.
Who is not a business associate?
Members of the covered entity's own workforce; true conduits that merely transport data, like couriers and internet service providers; and vendors that never touch patient information at all. The conduit exception is narrow — persistent storage or persistent access takes you out of it, which is why 'we're just the IT guys' rarely holds for an MSP managing a clinic's servers, email or backups.

Run one client free for 14 days.

Set up a single client organization, produce their evidence pack, and see how long it takes before you price it into a renewal.

Related: MSP console · Vendor compliance checker · BAA register

General information for service providers, not legal advice, and not a statement of how the rules apply to your particular arrangements. Whether you are a business associate depends on the facts of each engagement — take advice on the ones you are unsure about.